CVE-2017-1000364
38Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 5.2%
from disclosure to weapon484 days
Published on NVDJun 19
1st PoC+484d
metasploitJun 19
exploitation probability
5.2%top 8% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45625cve_referencewww.exploit-db.com/exploits/45625/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2017:1482https://access.redhat.com/errata/RHSA-2017:1483https://access.redhat.com/errata/RHSA-2017:1484https://access.redhat.com/errata/RHSA-2017:1485https://access.redhat.com/errata/RHSA-2017:1486https://access.redhat.com/errata/RHSA-2017:1487https://access.redhat.com/errata/RHSA-2017:1488https://access.redhat.com/errata/RHSA-2017:1489https://access.redhat.com/errata/RHSA-2017:1490https://access.redhat.com/errata/RHSA-2017:1491https://access.redhat.com/errata/RHSA-2017:1567https://access.redhat.com/errata/RHSA-2017:1616